SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 61916: The Export to Excel feature in SAS® Enterprise GRC and SAS® Model Risk Management contains security vulnerabilities

DetailsHotfixAboutRate It

Severity: High
Description: The Export to Excel feature of the web application might enable injection of malicious scripts into a cell of a Microsoft Excel spreadsheet.
Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note to access the hot fix for this issue.

With this fix, the web application escapes the text for any cell whose value begins with one of the following characters:

= @ + -

After you install the hot fix, you can specify additional characters to escape, by specifying the following configuration property in the configdata.properties file:

monitor.export.charsToEscape = characters_to_escape

For example, if you would like to escape the # character, you would add the character to the list of default characters, as shown in the following example:

monitor.export.charsToEscape = @=+-#


Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Enterprise GRCMicrosoft Windows Server 2003 Standard Edition5.1_M59.3 TS1M2
Microsoft Windows Server 2003 for x645.1_M59.3 TS1M2
Microsoft Windows Server 20085.1_M59.3 TS1M2
Microsoft Windows Server 2008 R25.1_M59.3 TS1M2
Microsoft Windows Server 2008 for x645.1_M59.3 TS1M2
Microsoft Windows Server 2012 Datacenter5.1_M59.3 TS1M2
Microsoft Windows Server 2012 R2 Datacenter5.1_M59.3 TS1M2
Microsoft Windows Server 2012 R2 Std5.1_M59.3 TS1M2
Microsoft Windows Server 2012 Std5.1_M59.3 TS1M2
Microsoft Windows XP Professional5.1_M59.3 TS1M2
Microsoft Windows Server 2003 Enterprise Edition5.1_M59.3 TS1M2
Microsoft Windows Server 2003 Datacenter Edition5.1_M59.3 TS1M2
Microsoft Windows 8.1 Pro x645.1_M59.3 TS1M2
Microsoft Windows 8.1 Pro 32-bit5.1_M59.3 TS1M2
Microsoft Windows 8.1 Enterprise x645.1_M59.3 TS1M2
Microsoft Windows 8.1 Enterprise 32-bit5.1_M59.3 TS1M2
Microsoft Windows 8 Pro x645.1_M59.3 TS1M2
Microsoft Windows 8 Pro 32-bit5.1_M59.3 TS1M2
Microsoft Windows 8 Enterprise x645.1_M59.3 TS1M2
Microsoft Windows 8 Enterprise 32-bit5.1_M59.3 TS1M2
Windows 7 Enterprise 32 bit5.1_M59.3 TS1M2
Windows 7 Enterprise x645.1_M59.3 TS1M2
Windows 7 Home Premium 32 bit5.1_M59.3 TS1M2
Windows 7 Home Premium x645.1_M59.3 TS1M2
Windows 7 Professional 32 bit5.1_M59.3 TS1M2
Windows 7 Professional x645.1_M59.3 TS1M2
Windows 7 Ultimate 32 bit5.1_M59.3 TS1M2
Windows 7 Ultimate x645.1_M59.3 TS1M2
Microsoft® Windows® for x645.1_M59.3 TS1M2
Windows Vista5.1_M59.3 TS1M2
Windows Vista for x645.1_M59.3 TS1M2
64-bit Enabled AIX5.1_M59.3 TS1M2
64-bit Enabled Solaris5.1_M59.3 TS1M2
HP-UX IPF5.1_M59.3 TS1M2
Linux for x645.1_M59.3 TS1M2
Solaris for x645.1_M59.3 TS1M2
SAS SystemSAS Model Risk ManagementMicrosoft® Windows® for x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Enterprise 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Enterprise x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Pro 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Pro x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Enterprise 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Enterprise x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Pro 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Pro x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 106.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 20086.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2008 R26.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2008 for x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 Datacenter6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 R2 Datacenter6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 R2 Std6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 Std6.17.49.4 TS1M29.4 TS1M5
Windows 7 Enterprise 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Enterprise x646.17.49.4 TS1M29.4 TS1M5
Windows 7 Home Premium 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Home Premium x646.17.49.4 TS1M29.4 TS1M5
Windows 7 Professional 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Professional x646.17.49.4 TS1M29.4 TS1M5
Windows 7 Ultimate 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Ultimate x646.17.49.4 TS1M29.4 TS1M5
64-bit Enabled AIX6.17.49.4 TS1M29.4 TS1M5
64-bit Enabled Solaris6.17.49.4 TS1M29.4 TS1M5
HP-UX IPF6.17.49.4 TS1M29.4 TS1M5
Linux for x646.17.49.4 TS1M29.4 TS1M5
Solaris for x646.17.49.4 TS1M29.4 TS1M5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.